CVE-2021-33723: Medium severity siemens sinec nms sp1 update 1 vulnerability
Published Oct 12, 2021
·Updated
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any user without proper authorization. With this, the attacker could change the password of any user in the affected system.
Affected Software
4 affected components
Siemens SINEC NMS<1.0
Siemens SINEC NMS=1.0
Siemens SINEC NMS=1.0-sp1
Siemens SINEC NMS=1.0-sp2
Remediation
Event History
Oct 12, 2021
CVE Published
via MITRE·09:49 AM
Data Sourced
via MITRE·09:49 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-33723.
2
What is the affected software?
The affected software is Siemens SINEC NMS.
3
What is the severity of CVE-2021-33723?
The severity of CVE-2021-33723 is medium.
4
How can an attacker exploit CVE-2021-33723?
An authenticated attacker could change the user profile of any user without proper authorization.
5
Is there a fix for CVE-2021-33723?
Yes, updating to SINEC NMS V1.0 SP2 Update 1 or later will fix the vulnerability.